Skip to content
ossscanner.org

May 17, 2026

Linux kernel sets rules for AI-assisted security reports

Short plain-text reports, verifiable impact, a tested reproducer shared on request and a tested fix with a Fixes: tag. Torvalds calls the private security list almost unmanageable.

In May 2026 the kernel merged new documentation, written by Willy Tarreau and acked by Greg Kroah-Hartman, on responsible use of AI to find bugs. The security list had gone from two or three reports a week to five to ten a day, many of them duplicates found with the same tools.

The rules ask reporters to put a clear summary first and keep reports short; convert them to plain text without Markdown; stick to verifiable impact under the kernel's threat model; always provide and test a reproducer, sharing it only on maintainers' request; and propose a tested fix with a Fixes: tag naming the commit that introduced the bug.

Linus Torvalds added that AI-detected bugs are by definition not secret and should go directly to maintainers. These rules shaped ossscanner.org: concise reports, verification before output, a patch and introducing commit for every finding, and reproducers revealed only to maintainers.

Want to see what an AI audit finds in your project? Quick scans are free and take a few minutes.

Scan a repository